CVE-2025-66376MEDIUM 6.1CISA KEVEPSS p95.6%

CVE-2025-66376Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting Vulnerability

Synacor / Zimbra Collaboration Suite (ZCS)

Description

Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting vulnerability in the Classic UI where attackers could abuse Cascading Style Sheets (CSS) @import directives in email HTML.

Scoring

CVSS 3.16.1 (MEDIUM)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS12.01% probability of exploitation · percentile 95.6% · 2026-06-18T12:00:27Z
Published2026-01-05
Last modified2026-03-18

CISA KEV entry

Added to KEV: 2026-03-18

Underlying weaknesses· 1

CWE-79

References

  1. https://wiki.zimbra.com/wiki/Security_Center
  2. https://wiki.zimbra.com/wiki/Zimbra_Releases/10.0.18#Security_Fixes
  3. https://wiki.zimbra.com/wiki/Zimbra_Releases/10.1.13#Security_Fixes
  4. https://wiki.zimbra.com/wiki/Zimbra_Responsible_Disclosure_Policy
  5. https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories
  6. https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-66376

1

TypeTargetConfidenceTier
WeaknessImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting')cwe-790%live

(incoming)1

TypeTargetConfidenceTier
KEVEntrySynacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting Vulnerabilitykev-cve-2025-663760%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability
CVE
Synacor Zimbra Collaborate Suite (ZCS) Cross-Site Scripting Vulnerability
CVE
Synacor Zimbra Collaboration Suite (ZCS) PHP Remote File Inclusion Vulnerability
CVE
Synacor Zimbra Collaboration Suite (ZCS) Server-Side Request Forgery (SSRF) Vulnerability
CVE
Synacor Zimbra Collaboration Suite (ZCS) Server-Side Request Forgery Vulnerability
CVE
Synacor Zimbra Collaboration Suite (ZCS) Authentication Bypass Vulnerability
Sourced from NVD + CISA KEV + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.